Africa’s AI Security Gap Leaves Organizations Vulnerable

African organizations face a pressing challenge as they adopt agentic AI: their existing security models are ill-equipped to handle the autonomy of these systems. Kerissa Varma, Chief Security Advisor at Microsoft Africa, highlights that the core issue is not AI’s intelligence, but its ability to act independently.
Traditional security strategies have focused on countering human-driven attacks. However, AI agents can reason, adapt, and operate at machine speed, outpacing conventional defenses. A survey by MIT Sloan Management Review and BCG found that 82% of African respondents view AI agents as colleagues rather than tools, indicating their growing integration into workflows.
A New Security Paradigm
The rapid adoption of AI in sectors like financial services and logistics in countries such as Kenya, Nigeria, and South Africa has outpaced the development of governance frameworks. This gap leaves organizations vulnerable to increasingly autonomous cyberthreats. A Dark Reading survey identified agentic AI as the most dangerous attack vector for modern infrastructure.
Redesigning Security for Autonomy
Varma argues that simply adding more AI to existing workflows is insufficient. Instead, organizations must redesign their security around a cyber stack tailored for autonomy. This stack includes signals and sensors for awareness, security context to interpret signals, models for intelligence, and a harness to coordinate models and agents.
These components form a continuous learning system that adapts to risks and improves security over time. Cybersecurity now relies on dynamic, adaptive systems that evolve with threats, rather than static defenses.
The Role of Context and Intelligence
Context is vital in this new model. Raw signals from identities, devices, and applications often lack the broader organizational context needed for accurate risk assessment. Autonomous systems require a shared, continuously updated understanding of their environment to differentiate genuine threats from normal behavior.
Applying the right intelligence to the right problem is also key. Different security tasks, such as investigating suspicious sign-ins or analyzing malware, require distinct reasoning and expertise. A multi-model architecture enables organizations to match appropriate intelligence to each task, balancing quality, reliability, and cost.
Turning Insight into Action
Intelligence without action is ineffective. Actuators are essential for translating insights into protective measures. By linking detection, decision-making, and response, actuators help organizations continuously reduce risks instead of just reporting them.
Varma emphasizes that the cyber stack’s layers—signals, context, models, and harness—must work cohesively to create a system capable of learning and adapting. This approach ensures that security measures evolve in tandem with the threats they aim to counter.
Balancing Security and AI Evolution
Trust is fundamental across all cybersecurity layers. As autonomy increases in security operations, safety, governance, and accountability must be integral from the start, not added later. Clear guidelines for AI operations, explainable and auditable decisions, and strict oversight of data, access, and compliance are essential.
